Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
In the past WebYAST was installed with world readable
secret tokens. Although these were modified on the start
of the webyast service and so could not be read from
remote, it was possible for local attackers on the same
machine to read the secrets and so gain local root access
via the webyast services. This has been fixed.
(CVE-2013-3709)
Security Issue reference:
* CVE-2013-3709
#851116
Cross- CVE-2013-3709
Affected Products:
WebYaST 1.2
https://www.suse.com/security/cve/CVE-2013-3709.html
Get the latest Linux and open source security news straight to your inbox.